Sending Out an SMS: Characterizing the Security of the SMS Ecosystem with Public Gateways
Bradley Reaves, Nolen Scaife, Dave Tian, Logan Blue, Patrick Traynor, Kevin R. B. Butler
Abstract
Text messages sent via the Short Message Service (SMS) have revolutionized interpersonal communication. Recent years have also seen this service become a critical component of the security infrastructure, assisting with tasks including identity verification and second-factor authentication. At the same time, this messaging infrastructure has become dramatically more open and connected to public networks than ever before. However, the implications of this openness, the security practices of benign services, and the malicious misuse of this ecosystem are not well understood. In this paper, we provide the first longitudinal study to answer these questions, analyzing nearly 400,000 text messages sent to public online SMS gateways over the course of 14 months. From this data, we are able to identify not only a range of services sending extremely sensitive plaintext data and implementing low entropy solutions for one-use codes, but also offer insights into the prevalence of SMS spam and behaviors indicating that public gateways are primarily used for evading account creation policies that require verified phone numbers. This latter finding has significant implications for research combatting phone-verified account fraud and demonstrates that such evasion will continue to be difficult to detect and prevent. We note the very fact that some users are willing to intentionally direct text messages to public portals is obviously dangerous. We do not address this phenomenon and instead focus on the risks of compromise of the SMS channel. Because these messages are known by the recipient to be publicly available, this dataset would naturally not be entirely representative of all SMS activity of a typical user. Nevertheless, this dataset enables the first public insights into issues such
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers15
- New Security Threats Caused by IMS-based SMS Service in 4G LTE NetworksGuan-Hua Tu, Chi-Yu Li, Chunyi Peng, Yuanjie Li et al.CCS 2016 · 60 citations
- Lies in the Air: Characterizing Fake-base-station Spam Ecosystem in ChinaYiming Zhang, Baojun Liu, Chaoyi Lu, Zhou Li et al.CCS 2020 · 43 citations
- On SMS Phishing Tactics and InfrastructureAleksandr Nahapetyan, Sathvik Prasad, Kevin Childs, Adam Oest et al.S&P 2024 · 30 citations
- Characterizing Pixel Tracking through the Lens of Disposable Email ServicesHang Hu, Peng Peng, Gang WangS&P 2019 · 25 citations
- A nationwide census on wifi security threats: prevalence, riskiness, and the economicsDi Gao, Hao Lin, Zhenhua Li, Feng Qian et al.MobiCom 2021 · 14 citations
Related papers
- The Tragedy of Convenience: Cascading User-Data Leakage from SMS-delivered URLsMuhammad Danish, Enrique Sobrados, Priya Kaushik, Bhupendra Acharya et al.CCS 2026
- Clues in Tweets: Twitter-Guided Discovery and Analysis of SMS SpamSiyuan Tang, Xianghang Mi, Ying Li, XiaoFeng Wang et al.CCS 2022 · 31 citations
- Preventing Artificially Inflated SMS Attacks through Large-Scale Traffic InspectionJun Ho Huh, Hyejin Shin, Sunwoo Ahn, Hayoon Yi et al.USENIX Security 2025
- Thwarting Smartphone SMS Attacks at the Radio Interface LayerHaohuang Wen, Phillip A. Porras, Vinod Yegneswaran, Zhiqiang LinNDSS 2023
- Email Spoofing with SMTP Smuggling: How the Shared Email Infrastructures Magnify this VulnerabilityChuhan Wang, Chenkai Wang, Songyi Yang, Sophia Liu et al.USENIX Security 2025
